PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-15028 Red Hat CVE debrief

A flaw in libarchive allows remote attackers to trigger a heap overflow via a specially crafted tar archive, potentially leading to denial of service or arbitrary code execution. The issue arises during parsing of a PAX extended header containing a malformed SUN.holesdata sparse-file attribute. Successful exploitation could lead to system unavailability or attacker control. Defenders should assess exposure, particularly for systems handling tar archives, and prioritize remediation based on system criticality. The impact and remediation details require verification from official sources.

Vendor
Red Hat
Product
Red Hat Enterprise Linux 10
CVSS
LOW 3.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-10
Original CVE updated
2026-09-22
Advisory published
2026-07-10
Advisory updated
2026-09-22

Who should care

Defenders and administrators of systems handling tar archives, particularly those using libarchive, should assess exposure and prioritize remediation. System criticality should guide prioritization, and defenders should verify affected versions and systems. The vulnerability's impact on system availability and potential for arbitrary code execution necessitates prompt action.

Why it matters

CVE-2026-15028 is a heap overflow vulnerability in libarchive that could lead to denial of service or arbitrary code execution. Defenders should assess exposure, particularly for systems handling tar archives, and prioritize remediation based on system criticality. The impact and remediation details require verification from official sources.

  • Potential denial of service, making systems unavailable
  • Possible arbitrary code execution, allowing attacker control
  • Need to verify affected versions and systems
  • Remediation priority based on system criticality

Technical summary

The libarchive library is vulnerable to a heap overflow when parsing a specially crafted tar archive, specifically a PAX extended header with a malformed SUN.holesdata sparse-file attribute. This vulnerability could lead to denial of service or arbitrary code execution. Defenders should assess exposure, particularly for systems handling tar archives, and prioritize remediation based on system criticality. The impact and remediation details require verification from official sources. Affected product deployments need identification, and owners should be assigned for follow-up.

Defensive priority

Assess exposure and prioritize remediation for systems handling tar archives.

Recommended defensive actions

  • Assess exposure of systems handling tar archives
  • Prioritize remediation based on system criticality
  • Verify vendor-provided patches and updates
  • Review compensating controls for exposed systems
  • Check relevant monitoring, detection, and logs for exposed assets
  • Track exceptions, retest remediated assets
  • Confirm whether affected product deployments exist in managed environments

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but its impact and remediation require verification. Affected systems handling tar archives need assessment, and defenders should verify vendor-provided patches and updates. The vulnerability's exploitation could lead to denial of service or arbitrary code execution, emphasizing the need for prompt remediation.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-15028 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-15028

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-15028 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-15028

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.